RackTop Systems
Product

BrickStor CSfC DAR — Classified Data at Rest, Ready for the Fight

Data at rest protection designed to the NSA CSfC Capability Package, combined with the BrickStor platform's immutable audit and integrity monitoring. Higher performance and more deployment flexibility than Type 1, releasable for allied and coalition use, and engineered for tactical, shipboard, and airborne missions.

Why BrickStor CSfC DAR

Classified missions can't wait for yesterday's hardware

The adversary is moving at commercial speed. Classified data protection has to move with them — without compromising the rigor the NSA CSfC program demands. BrickStor CSfC DAR is engineered to deliver both, on hardware you can actually field this year.

Performance and Flexibility

Eliminate Type 1 encryption bottlenecks.

CSfC DAR on commercial NVMe Gen 5 flash delivers read and write performance Type 1 devices can't match — sustained throughput for ingest-heavy workloads, real-time analytics, and high-rate recording at the edge. The architecture is releasable for allied and coalition operations, available in multiple form factors, and refreshes on commercial cadence rather than waiting on the Type 1 supply chain.

Defense-in-Depth

Layered encryption plus classified-grade accountability.

Dual-layer commercial encryption protects classified data at rest. On top of that, the BrickStor platform adds immutable audit and integrity monitoring — so the platform protects against both the stolen-device scenario and the insider-misuse scenario.

Deployable Anywhere

Tactical, shipboard, airborne, expeditionary.

Classified missions increasingly operate outside SCIFs and fixed data centers. BrickStor CSfC DAR is engineered for forward-deployed and mobile platforms — with ruggedized options and a commercial refresh cadence matched to how fast missions evolve.

Program Outcomes

What CSfC on BrickStor delivers to program offices

Higher
Read and write performance vs. Type 1

Commercial NVMe Gen 5 flash delivers sustained throughput Type 1 can't match — for ingest, analytics, and recording at the edge.

Dual-Layer
Commercial encryption, defense-in-depth

Two independent, NSA-approved encryption layers protect classified data at rest.

One
Platform for classified DAR + accountability

Layered encryption, immutable audit, and integrity monitoring in a single accredited stack.

DAR 5.1
Designed to the NSA CSfC Capability Package

In Common Criteria evaluation now; Components listing expected Q4 2026.

How BrickStor CSfC DAR is different

Most CSfC DAR stops at encryption.
BrickStor delivers audit and accountability.

The CSfC capability package covers the encryption architecture. It doesn't detect tampering of classified data, and it doesn't produce the audit trail an IG will ask for. BrickStor does — on the same accredited platform.

01

Performance, flexibility, and allied use Type 1 can't match

Type 1 devices remain essential for specific use cases — but they cap performance, restrict deployment, and carry significant consequence if a device is lost or compromised in the field. CSfC DAR on BrickStor delivers higher read and write throughput on commercial NVMe, releases cleanly for allied and coalition operations where Type 1 is restricted, and limits exposure if hardware is lost — a cleared zeroize, not an international incident.

02

More than encryption — audit and accountability

Most CSfC DAR offerings stop at the encryption layer. BrickStor adds the accountability classified missions require — immutable audit supporting investigations and integrity monitoring defending against tampering.

Core Capabilities

Built for classified data at the edge

CSfC Data at Rest Protection

NSA CSfC

Architecture designed to the NSA Commercial Solutions for Classified (CSfC) Data at Rest Capability Package protects classified data at rest using dual layered commercial encryption.

Classified Edge Deployment

Edge

Purpose-built for tactical, mobile, and edge environments where classified data must be protected outside of traditional SCIFs and data centers.

Layered Encryption

Core

Dual-layer encryption architecture meets CSfC Data at Rest Capability Package requirements for protecting classified information on commercial hardware.

High-Speed Data Recorder

Optional

Optional High-Speed Data Recorder (HDR) functionality can be added to the CSfC DAR platform — combining classified-ready data protection with lossless high-rate recording for ISR, SIGINT, radar, and test-range missions.

Explore BrickStor HDR

RackTop SHIELD

CSfC Component

Designed to be the outer layer, handling the Authorization Acquisition (AA) function for CSfC listed drives. Ships in this platform and is available separately.

Explore RackTop SHIELD

RackTop SPEAR

CSfC Component

Software-based Full Drive Encryption implementing both the AA and EE functions, designed to be the inner encryption layer. Ships in this platform and is available separately.

Explore RackTop SPEAR

High-Performance NVMe

Performance

PCIe Gen 5 NVMe flash delivers the bandwidth and IOPS required for the most demanding classified workloads — sustained ingest, real-time analytics, and high-rate recording at the tactical edge.

Immutable Audit & Accountability

Core

Immutable, tamper-evident audit logging provides accountability for all access to classified data, supporting security reviews, SIRs, and incident investigations.

Mission Areas

Deployed where the mission demands

Tactical Edge

Protect classified data on forward-deployed, mobile, and expeditionary platforms where physical security is limited.

Shipboard & Maritime

Classified data storage and protection for naval vessels and maritime platforms operating in contested environments.

Airborne Systems

Secure classified data capture and storage for airborne ISR, C2, and mission systems.

CSfC Advantage

Why CSfC for classified data at rest

The NSA CSfC program enables agencies and commands to use layered commercial encryption to protect classified data — delivering higher performance, broader deployment flexibility, and use cases (including allied and coalition operations) that traditional Type 1 encryption devices can't support.

Higher read and write performance than Type 1 on commercial NVMe Gen 5 flash
Releasable for allied and coalition operations where Type 1 is restricted
Lower consequence-of-loss — a compromised device is a cleared zeroize, not an international incident
Commercial refresh cycles keep pace with evolving threats and platforms
Dual-layer commercial encryption provides defense-in-depth for classified DAR
BrickStor adds integrity monitoring, immutable audit, and accountability beyond encryption

Frequently asked questions

CSfC (Commercial Solutions for Classified) Data at Rest is an NSA program that enables the use of layered commercial encryption products to protect classified data at rest — an alternative to Type 1 encryption devices that delivers higher performance, broader deployment flexibility, and releasability for allied and coalition use.
CSfC architectures protect classified data up to Top Secret; the level a given deployment supports is determined by its registered solution architecture. BrickStor CSfC DAR is designed to the CSfC Data at Rest Capability Package for classified data on commercial hardware in tactical and edge environments. Contact RackTop to discuss the classification levels and architecture for your program.
Type 1 devices remain essential for specific use cases. CSfC is typically chosen when programs need higher read and write performance than Type 1 can deliver, the flexibility to operate with allied and coalition partners, and lower consequence-of-loss if hardware is compromised in the field — a cleared zeroize event rather than the incident response a lost Type 1 device triggers. CSfC also brings commercial refresh cadence and a lower total cost of ownership without lowering the bar on protection of classified information at rest.
BrickStor CSfC DAR adds the dual-layer encryption architecture of the NSA CSfC Data at Rest Capability Package on top of the BrickStor SP Cyberstorage platform. It is specifically designed for environments where classified data must be stored and protected outside of traditional secure facilities.
Yes. BrickStor CSfC DAR is engineered for tactical, mobile, shipboard, airborne, and expeditionary deployments where classified data must be protected with limited physical security infrastructure.

Classified Data Protection, Ready for the Edge

BrickStor CSfC DAR delivers classified data at rest protection designed to the NSA CSfC DAR Capability Package, with the performance and flexibility commercial hardware brings — releasable for allied use, lower consequence-of-loss in contested environments, and immutable audit and integrity monitoring on top.

NSA CSfC Component listing for AA and AA+EE expected in Q4 2026.

CSfC Data at Rest Storage With Dual-Layer Encryption